Hi all,
While serving in the military, I found certain vulnerabilities in a homegrown iOS MDM application developed by the NCSIST for the Ministry of National Defense. These flaws could pose a threat if exploited, allowing soldiers on military installations to bypass measures set by the MDM app to steal military secrets.
At this stage, I've done some research and reverse-engineering though decompiling the app, running static and dynamic analysis, and scrutinizing its security architecture.
I intend to compile my findings into a more comprehensive report that could be presented to the Ministry of Defense, and I'm considering to raise awareness on this and to propose a idea of a community-backed open-source project at the next g0v meetup to address these issues.
What I'm hoping is to develop a open-source alternative that not only improves security within the RoC military, but also serves as a on-premise solution for BYOD policies in companies.
😵💫 1
😮 2
👀 1